npm

@gocortexio/npmgremlinbox-agpl-3-0-only @2.1.0

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-10787

Ecosystem

npm

Summary

No a static rule matches and no traced installer-harm behaviors were identified in this package version. No lifecycle scripts, credential access patterns, network exfiltration endpoints, or install-time fetch-and-execute mechanisms surfaced during analysis of the scanned files.

Source: amazon-inspector (3fbd1a1acff8225ac5ce7f3c19a6eb207a79bc1aa842de64d0f697eda839c021)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.